HIGH

CVE-2026-81090

2026-09-12 CVSS v3.1
CVSS
7.2

Description

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.

Weakness (CWE)

CWE-352 Cross-Site Request Forgery (CSRF)
CWE-434 Unrestricted File Upload

EPSS Score

0.27%
Probability of exploitation in next 30 days
19.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE